Gramm-Leach-Bliley Act — FTC Safeguards Rule and Privacy Rule
The FTC Safeguards Rule's required elements of a written information security program, plus the core privacy notice and opt-out duties of the GLBA Privacy Rule. Each control cites the paragraph it derives from.
US Federal Trade Commission (Safeguards Rule); CFPB (Regulation P) · 16 CFR Part 314 as amended 2021 and 2023 (FTC notification duty in force since 13 May 2024); Regulation P, 12 CFR Part 1016 · United States — non-bank financial institutions under FTC jurisdiction (lenders, mortgage brokers, tax preparers, auto dealers, fintechs, payment and wealth services and similar) · Official source
The institution designates a single Qualified Individual responsible for overseeing, implementing and enforcing its written information security program. The Qualified Individual may be an employee, or work for an affiliate or service provider — in which case the institution keeps responsibility, designates senior personnel to oversee them, and requires the provider to maintain a compliant program.
The information security program is based on a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information, sets criteria for evaluating and categorising risks, assesses the adequacy of existing controls, and describes how risks will be mitigated or accepted; additional risk assessments are performed periodically.
Technical and, as appropriate, physical access controls authenticate and permit access only to authorised users, and limit each user's access to the customer information they need to perform their duties; access is reviewed periodically.
The institution identifies and manages the data, personnel, devices, systems and facilities that enable it to achieve business purposes, in accordance with their relative importance to business objectives and the organisation's risk strategy.
All customer information held or transmitted is encrypted, both in transit over external networks and at rest. Where encryption is infeasible, the Qualified Individual may approve effective alternative compensating controls, which must be reviewed.
Secure development practices are adopted for in-house developed applications used to transmit, access or store customer information, and procedures exist for evaluating, assessing or testing the security of externally developed applications the institution uses.
Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.
Customer information is securely disposed of no later than two years after the last date it was used to provide a product or service to the customer, unless it is needed for business operations or other legitimate purposes, required by law, or targeted disposal is infeasible; the data retention policy is reviewed periodically to minimise unnecessary retention.
Procedures for change management govern changes to information systems and networks.
Policies, procedures and controls monitor and log the activity of authorised users and detect unauthorised access to, use of, or tampering with customer information by those users.
The effectiveness of safeguards is regularly tested or monitored. For information systems this means continuous monitoring, or annual penetration testing plus vulnerability assessments (including systemic scans) at least every six months, whenever there are material changes, and whenever circumstances may have a material impact.
Personnel receive security awareness training updated to reflect risks identified by the risk assessment; qualified information security personnel (employed or via a provider) manage the program; and those personnel receive security updates and training sufficient to address relevant risks, with their knowledge of changing threats verified.
Service providers are overseen by taking reasonable steps to select and retain providers capable of maintaining appropriate safeguards, requiring them by contract to implement and maintain such safeguards, and periodically assessing them based on the risk they present and the continued adequacy of their safeguards.
The information security program is evaluated and adjusted in light of testing and monitoring results, material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on it.
A written incident response plan is designed to promptly respond to and recover from any security event materially affecting customer information. It addresses the plan's goals, internal response processes, clear roles and decision-making authority, internal and external communications, remediation of identified weaknesses, documentation and reporting of events, and evaluation and revision after events.
The Qualified Individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body — or to a senior officer if there is no board — on the overall status of the program and compliance with the Safeguards Rule, and on material matters such as risk assessment, risk management decisions, service provider arrangements, testing results, security events and recommended changes.
When the institution discovers a notification event — unauthorised acquisition of unencrypted customer information — involving the information of at least 500 consumers, it notifies the FTC through its online form as soon as possible and no later than 30 days after discovery, including the types of information involved, the date or range of the event, the number of consumers affected and a general description.
Customers receive a clear and conspicuous privacy notice when the customer relationship begins and annually for as long as it continues — unless the annual-notice exception applies (sharing only within the exceptions and no change to policies) — describing the categories of nonpublic personal information collected and disclosed, the categories of recipients, information-sharing practices, the right to opt out, and how the information is protected.
Before disclosing nonpublic personal information to a nonaffiliated third party outside the statutory exceptions, the institution gives the consumer notice and a reasonable opportunity to opt out (for example 30 days and a toll-free number or online form), and honours opt-outs promptly.